Skip to content

Tunnels — expose a local port on a public {name}.maxoperf-tunnel.com URL

A tunnel exposes a port on your machine (or anywhere else something is listening) on a public, TLS-terminated URL: https://<name>.maxoperf-tunnel.com. It is MaxoPerf’s reverse-tunnel service, in the same family as ngrok, and it is completely free on every plan. MaxoPerf never bills tunnels, on any tier.

Terminal window
npx @maxoperf/tunnel http 3000
✔ guest tunnel online https://swift-otter-7f3.maxoperf-tunnel.com → http://127.0.0.1:3000

That is the whole zero-signup path: no account, no API key, no config file. See Create a tunnel for the full CLI, console, and API flows.

Get started with tunnels.
  • Show someone a local build. Point a teammate, a client, or a webhook provider at a URL that reaches your laptop.
  • Test webhooks against a local server. Stripe, GitHub, or any provider that needs a public callback URL can hit your tunnel and forward straight to your local dev server.
  • Expose a MaxoPerf virtual service or run for external access without deploying it anywhere else first.
  • Quick demos. A tunnel URL is live as soon as the CLI connects. No deploy pipeline.
Guest modeAccount tunnel
Setupnpx @maxoperf/tunnel http <port>, nothing elseCreate via console/API/MCP first, then run the CLI with its token
SubdomainAuto-generated (e.g. swift-otter-7f3), stable across runs on the same machineYou choose the name (<name>.maxoperf-tunnel.com)
Concurrent tunnels110 on the free tier, up to 200 on Pro, unlimited on Enterprise
Security & InterstitialAnti-phishing warning screen for browser visitors (bypassable)Direct connection (zero interstitial)
Access controls (IP allow/deny, basic/bearer auth, rate limit)Fixed, safe defaults; not configurableFully configurable
Request capture (headers/body, for the inspector + replay)OffConfigurable (headers or headers+body)
Idle timeoutFixed at 1 hourConfigurable (default 1 hour)

The guest identity is a durable token the CLI saves locally (~/.maxoperf/tunnel.json, file mode 0600), so re-running the CLI on the same machine reuses the same URL every time. That lasts until you claim it into an account or it expires. Claiming keeps the URL and turns on the account-tunnel features above, with no downtime.

Anonymous guest tunnels show a security interstitial before they forward browser traffic. It protects visitors from credential theft and protects MaxoPerf’s domain reputation against automated blacklists (e.g., Google Safe Browsing):

  • Browser warning: When a visitor opens an anonymous guest tunnel in a web browser, they see an unverified developer warning:

    “You are visiting a developer reverse tunnel hosted through MaxoPerf. Never enter passwords, credit cards, or personal credentials on this page.”

  • One-click proceed: Visitors acknowledge the notice by clicking Proceed to Developer Tunnel. This sets a session cookie (__mptt_skip_warning=1) and forwards them to the destination application right away.
  • Bypass for APIs and automated tools: Non-browser clients and automated workflows can skip the warning without receiving any HTML:
    • Add the header X-MaxoPerf-Skip-Browser-Warning: 1 (or ngrok-skip-browser-warning: 1 for drop-in compatibility with existing scripts).
    • Standard non-browser User-Agent strings (such as curl, API clients, SDKs, webhooks, and automated test runners) bypass the interstitial automatically.
  • Authenticated account tunnels: Tunnels that authenticated MaxoPerf accounts create never display an interstitial screen. Traffic connects directly.
  • Real TLS, terminated at the edge with automated wildcard certificates. Account tunnels show no interstitial.
  • WebSocket and SSE pass straight through. A websocket-based dev server or a streaming endpoint works through the tunnel unchanged.
  • Automatic reconnect. If your local network drops, the CLI reconnects with backoff and the tunnel comes back online on the same URL.
  • Full traffic statistics: request counts, error rates, latency percentiles, and bytes in/out, on a live timeline (account tunnels; see Create a tunnel).
Every tunnel on your account in one place: the public URL it answers on, and whether a client is holding it open right now.